Description
Multiple information disclosure vulnerabilities have been found in Microsoft SQL Server. Malicious user can exploit these vulnerabilities to obtain sensitive information. These vulnerabilities can be exploited remotelly via speculative execution side-channel attack to obtain sensetive information.
All Kaspersky Lab business and consumer products are compatible with the update. Our database update on 28th December enables the compatibility flag, recommended by Microsoft, to allow devices to apply the update from 3rd January.Further details of Kaspersky Lab compatibility with Microsoft security updates are on our Support page.Our recommendation remains that for optimum protection against vulnerabilities, software and operating system updates should be installed as soon as possible.More about the CPU vulnerabilities can be found on the Kaspersky Lab blog here and on the announcement website here.
Original advisories
Related products
CVE list
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com